Startups

Staff/Lead Application Security Engineer

Beacon · San Francisco, CA · On-site

← All jobs
About Beacon

Beacon acquires and grows essential businesses. With our centralized platform, we empower founders with the technology and expertise to better serve their customers. Backed by General Catalyst.

About the role

You will be Beacon's first dedicated application security engineer. You will set the strategy for product security and start to build the program.

What they're looking for

  • Would rather build a system that finds every instance of a bug than fix one at a time
  • Already uses AI as part of how you work, with real opinions on where it helps and where it doesn't, including judgment on when to build tooling versus buy it
  • Can set architecture and standards across many codebases, not just review one at a time
  • Ships production code yourself. You should be able to author a fix, not only specify it
  • Expert knowledge of web and API security, identity and access design (authentication, authorization, RBAC/ABAC), and applied cryptography
  • Experience securing applications in cloud environments and containerized workloads
More about this role

You will be Beacon's first dedicated application security engineer. You will set the strategy for product security and start to build the program.

Beacon's application security surface spans both Beacon's own engineering and our portfolio companies' products, each independently built with its own stack and engineering team. You will embed with the teams that own the code, whether at Beacon HQ or within a portfolio company, working inside their design reviews and planning, and own the technical roadmap for product security as Beacon grows.

This is the full remit of Application Security at Beacon. It is more than one person can cover at once. As the first member of the team, you will stand up the essentials, prioritize the highest-leverage work first, and build the rest into a roadmap.

Secure design and architecture: lead threat modeling and security architecture review for new product work and platform initiatives, and define standards for authentication, authorization, encryption, and tenant isolation.

Acquisition assessment: own the product security review of newly acquired codebases and cloud environments, establishing baseline posture, material risk, and the remediation...

Read the full posting on Beacon's site ↗

GRC / IT / Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.